OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Doug Monroe (monwel_at_interhack.net)
Date: Thu Jul 25 2002 - 08:59:59 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    "http-equivexcite.com" wrote:
    >
    > Tuesday, July 23, 2002
    > Trivial silent delivery and installation of an executable on a target
    > computer. This can be accomplished with the default installation of
    > the mail client Eudora 5.1.1:
    > 'allow executables in HTML content' DISABLED
    > 'use Microsoft viewer' ENABLED
    [snip]
    > Working Example:
    [snip]
    > http://www.malware.com/boodora.txt
    >
    > Notes: disable 'use Microsoft viewer'

    A Eudora expert I am not, but I suppose one could also change
      HKCU/software/qualcomm/eudora/launchmanager/path#2
    from
    "c:\windows\application data\qualcomm\eudora\embedded"
     or
    "c:\program files\qualcomm\eudora pro\embedded"
    to some other, non-default folder name.
    New folder must exist before running eudora again.

    And... add mhtml to "WarnExtentions#X" key values?